MetaMask has acknowledged an "ongoing security incident" affecting part of its infrastructure, while separate reports claim that Ethereum validators tied to the company have begun exiting — a detail the company itself has not confirmed.

The software wallet maker said on Thursday, 1 October 2026, that it is "actively addressing and remediating the issue internally, in coordination with external partners and security advisors." It added: "At this time, we have identified no immediate threat to MetaMask wallets."

Those two sentences are the extent of what MetaMask has put on the public record. The company has not described which part of its infrastructure is involved, what caused the incident, whether user funds or credentials are affected, or how many people or systems are in scope.

The validator-exit signal

The validator-exit detail does not come from MetaMask. It comes from reporting by The Hacker News, which states that validators associated with MetaMask and developer ConsenSys are exiting as part of the incident's fallout. That report is the sole source of the signal — it should be attributed to The Hacker News, not to the company.

The detail is unconfirmed in our coverage. Exit queues and validator activity are publicly observable on-chain, but we did not obtain independent confirmation of validator status tied to MetaMask or ConsenSys before filing. MetaMask's statement makes no reference to validators, staking, or exit queues. Readers should treat the validator-exit detail as reported, not established fact.

Reading the "no immediate threat" wording

MetaMask's phrasing deserves precise attention. "No immediate threat" is the company's present-tense assessment, made at a moment when it is still remediating an ongoing incident — a statement about timing as much as about safety. It is not a guarantee about the incident's eventual scope, and MetaMask has not addressed that question either way.

Reader guidance: what to do now

(The guidance below is HKLUG's own practical advice, drawn from established patterns in wallet-security scams — not from MetaMask or any regulator. Hong Kong's Anti-Deception Coordination Centre and CyberDefender appear strictly as reader resources.)

  • Official channels only. MetaMask does not request recovery or seed phrases through websites, email, phone calls, or support chats. Download wallets only from the official site or verified app-store listings, and check URLs character by character before entering any credential.
  • Expect a phishing wave. Security incidents reliably trigger follow-on scam campaigns impersonating wallet support, "migration" portals, "verification" prompts, or fake validator-exit refunds. Do not click links in unsolicited messages, and never approve a signature request you cannot fully explain.
  • Verify staking status independently. Anyone staking through validators associated with MetaMask or ConsenSys should confirm status via the companies' official communications and public on-chain explorers — never via unsolicited "alerts" or third-party messages.
  • Monitor official updates. Follow MetaMask's verified accounts and official status pages for the developing incident. Suspicious wallet prompts or messages can be reported to Hong Kong's Anti-Deception Coordination Centre or CyberDefender.

This story will be updated as MetaMask publishes further details.


MetaMask 已承認其部分基礎設施正受「一項持續中的安全事故」影響,另有獨立報道指與公司相關的以太坊驗證者已開始退出——但這一細節本身尚未獲公司證實。

這家軟件錢包開發商在 2026 年 10 月 1 日(星期四)表示,公司正「與外部合作夥伴及安全顧問協調,在內部積極處理並修復問題」,並補充:「目前,我們未發現 MetaMask 錢包面臨任何即時威脅。」

上述兩句話,就是 MetaMask 目前公開交代的全部內容。公司並未說明受影響的是哪一部分基礎設施、事故成因為何、用戶資金或憑證是否受到影響,以及涉及多少人或系統。

驗證者退出的訊號

有關驗證者退出的細節並非來自 MetaMask,而是來自 The Hacker News 的報道。該報道指出,與 MetaMask 及開發商 ConsenSys 相關的驗證者正以退場方式應對事故後果。該報道是這一訊號的唯一來源——其內容應歸於 The Hacker News 名下,而非來自公司本身。

此細節在我們的報道中仍未經證實。退出隊列及驗證者活動在鏈上屬公開可觀察的資料,但我們在發稿前未能就與 MetaMask 或 ConsenSys 相關的驗證者狀態取得獨立確認。MetaMask 的聲明中亦未提及驗證者、質押(staking)或退出隊列。讀者應將驗證者退出的細節視為「報道中」的說法,而非已確立的事實。

如何解讀「未發現即時威脅」的措辭

MetaMask 的措辭值得仔細留意。「未發現即時威脅」是公司對現狀的即時評估,作出時點正值公司仍在修復一場持續中的事故——這既是有關安全性的陳述,同樣也是關於時機的聲明。它並非對事故最終影響範圍的保證,而 MetaMask 亦未就此問題作出正面或負面的說明。

給讀者的建議:現在可以做些什麼

(下列建議屬 HKLUG 自行編撰的實用指引,參考過往錢包安全詐騙的常見模式——並非來自 MetaMask 或任何監管機構。下列香港的防騙易熱線(Anti-Deception Coordination Centre)及 CyberDefender 僅列作讀者資源。)

  • 只透過官方渠道。 MetaMask 不會透過網站、電郵、電話或客服對話,要求用戶提供帳戶復原資料或助記詞(seed phrase)。下載錢包只應使用官方網站或已核實的應用程式商店列表,並在輸入任何憑證前逐字核對網址。
  • 提防新一波釣魚詐騙。 安全事故過往屢屢觸發後續詐騙行動,例如冒充錢包客服、「遷移」門戶、「驗證」提示,或假冒的驗證者退出退款。切勿點擊未經請求的訊息中的連結,也絕不要批准你無法完全解釋的簽署請求。
  • 自行核實質押狀態。 透過與 MetaMask 或 ConsenSys 相關驗證者進行質押的用戶,應透過兩家公司的官方通訊及公開鏈上區塊瀏覽器(on-chain explorer)核實狀態——切勿依賴未經請求的「提示」或第三方訊息。
  • 留意官方更新。 追蹤 MetaMask 的認證帳戶及官方狀態頁面,以掌握事故的最新進展。可疑的錢包提示或訊息,可向香港的防騙易熱線(Anti-Deception Coordination Centre)或 CyberDefender 報告。

MetaMask 日後公布更多詳情時,本文將會更新。

新聞來源 / Original News Source